Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-0021

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2009-0021
Last Modified 30 Oct 2012 11:13:02
Published 07 Jan 2009 12:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2009-0021

Summary

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

Vulnerable Systems

Application

  • Ntp 4.2.0

  • Ntp 4.2.2

  • Ntp 4.2.4p1

  • Ntp 4.2.4p2

  • Ntp 4.2.4p3

  • Ntp 4.2.4p4


References

CERT - TA09-133A

MLIST - [announce] 20090108 NTP 4.2.4p6 Released

VUPEN - ADV-2009-1297

VUPEN - ADV-2009-0042

SECTRACK - 1021533

REDHAT - RHSA-2009:0046

MISC - http://www.ocert.org/advisories/ocert-2008-016.html

CONFIRM - http://support.apple.com/kb/HT3549

SLACKWARE - SSA:2009-014-03

SECUNIA - 35074

SECUNIA - 34642

SECUNIA - 33648

SECUNIA - 33558

SECUNIA - 33406

SUSE - SUSE-SR:2009:008

SUSE - SUSE-SR:2009:005

APPLE - APPLE-SA-2009-05-12

BUGTRAQ - 20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses

Related Patches

Apple 2009-05-12 Security Update 2009-002 Server (Tiger PPC)

Apple 2009-05-12 Security Update 2009-002 (Tiger PPC)

Apple 2009-05-12 Mac OS X 10.5.7 Combo Update

Apple 2009-05-12 Mac OS X Server 10.5.7 Update

Apple 2009-05-12 Mac OS X 10.5.7 Update

Apple 2009-05-12 Security Update 2009-002 (Tiger Intel)

Apple 2009-05-12 Mac OS X Server 10.5.7 Combo Update


Last Updated: 27 May 2016 10:49:48